Item - 2023.AU3.6
Tracking Status
- City Council adopted this item on December 13, 14 and 15, 2023 without amendments and without debate.
- This item was considered by Audit Committee on December 1, 2023 and was adopted with amendments. It will be considered by City Council on December 13, 14 and 15, 2023.
AU3.6 - Status Update on the City-wide Risk Governance Model
- Decision Type:
- ACTION
- Status:
- Adopted on Consent
- Wards:
- All
City Council Decision
City Council on December 13, 14, and 15, 2023, adopted the following:
1. City Council request the City Manager, in co-ordination with the Chief Technology Officer, the Chief Information Security Officer, the Executive Director, Toronto Emergency Management, and the Director, Internal Audit, to report to the Audit Committee in the third quarter of 2024 with an update on the implementation and maturation of Enterprise Risk Management.
2. City Council request the City Manager, in co-ordination with Director, Internal Audit to work with division heads to expand the inclusion of risk management considerations into reports provided to Committees and Council as applicable.
Background Information (Committee)
https://www.toronto.ca/legdocs/mmis/2023/au/bgrd/backgroundfile-240773.pdf
AU3.6 - Status Update on the City-wide Risk Governance Model
- Decision Type:
- ACTION
- Status:
- Amended
- Wards:
- All
Committee Recommendations
The Audit Committee recommends that:
1. City Council request the City Manager, in co-ordination with the Chief Technology Officer, the Chief Information Security Officer, the Executive Director, Toronto Emergency Management, and the Director, Internal Audit, to report to the Audit Committee in the third quarter of 2024 with an update on the implementation and maturation of Enterprise Risk Management.
2. City Council request the City Manager, in co-ordination with Director, Internal Audit to work with division heads to expand the inclusion of risk management considerations into reports provided to Committees and Council as applicable.
Origin
Summary
This report outlines the governance model, processes, and activities that will contribute to overall Enterprise Risk Management within the City. Enterprise Risk Management (ERM) is a structured, consistent, and continuous process that supports the achievement of the organization's objectives by identifying, assessing, responding to, and reporting on the full spectrum of risk, holistically across the organization. It also manages the combined impact of those risks as an interrelated risk portfolio.
The report provides an overview of the proposed City-wide Risk Governance Model. The governance model outlines roles and responsibilities within the Enterprise Risk Management process with respect to oversight of risks throughout the organization, including risks pertaining to business continuity, cyber major incident, and technology disaster recovery.
While divisions across the City including Technology Services, the Office of the Chief Information Security Officer and Toronto Emergency Management have employed their own processes to manage and govern their respective risks, Enterprise Risk Management takes a holistic approach to risk management looking at risks from a City-wide perspective.
Background Information
https://www.toronto.ca/legdocs/mmis/2023/au/bgrd/backgroundfile-240773.pdf
Motions
That:
1. City Council request the City Manager, in co-ordination with the Chief Technology Officer, the Chief Information Security Officer, the Executive Director, Toronto Emergency Management, and the Director, Internal Audit, to report to the Audit Committee in the third quarter of 2024 with an update on the implementation and maturation of Enterprise Risk Management.
2. City Council request the City Manager, in co-ordination with Director, Internal Audit to work with division heads to expand the inclusion of risk management considerations into reports provided to Committees and Council as applicable.